• Send Us A Tip
  • Calling all Tech Writers
  • Advertise
Monday, June 22, 2026
  • Login
TechStory
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
TechStory
No Result
View All Result
Home Crypto

Inside Brazil’s $100 Million PIX Cyber-Heist: How an Insider Unlocked the Vault

by Anindya Paul
July 9, 2025
in Crypto
Reading Time: 4 mins read
0
PIX

Source: Intelligent CIO

TwitterWhatsappLinkedin

Brazilian police have opened an investigation into a shocking cyber-heist that saw at least 540 million reais ( $100 million) stolen from financial institutions in a single night. Here is a case study of how an insider’s treachery circumvented the PIX payment system – and what investigators are doing to rectify it.

You might also like

Japan’s Pension Sector Tests the Waters: Corporate Fund to Allocate 1% to Cryptocurrency

BRC-20 Tokens Explained: What They Are and How They Work on Bitcoin

How Bitcoin ETF Taxes Work: A Complete Guide for Investors

What Happened?

Right after midnight on June 30, 2025, C&M Software was victimized by hackers. C&M is a critical service that provides connectivity between Banco do Brasil and Brazil’s instant payment service, called PIX. The hackers used stolen credentials purchased from a compromised insider who sold their credentials. Shortly after compromise, the so-called “hackers” began executing fake PIX transfers against the reserve accounts of six financial institutions at the same time. Estimates show losses ranging from 540 million reais ($100 million) to an upper estimate of 800 million reais ($140 million).

The Insider: João Roque’s Role

Police in São Paulo have apprehended João Nazareno Roque, a 48 year old IT employee at C&M. Roque is accused of selling his system access—including login credentials—for around R$15,000 (≈ $2,700). Reports suggest he facilitated remote access and even helped set up the fraudulent transfer framework. He allegedly claimed the recruitment started earlier this year, initiated through casual contact at a bar and later coordinated via phone and WhatsApp.

Mechanism of the Heist

Once armed with Roque’s credentials, the attackers accessed C&M’s back-end systems—the “bridge” to Pix infrastructure—and launched coordinated fake transfers lasting around 2.5 hours. These operations specifically hit reserve accounts used between institutions, which shielded consumer accounts and prevented public panic.

Follow-the-Money: Crypto Laundering

Investigators and blockchain analysts, including ZachXBT, tracked about $30 to $40 million of the stolen funds funnelled into Bitcoin, Ethereum, and USDT via Latin American OTC exchanges. Authorities have successfully frozen approximately 270 million reais (~$50 million) of illicit assets so far.

Institutional Responses

  • Central Bank of Brazil immediately suspended parts of C&M’s access to the PIX network and ordered stricter security oversight following the breach.
  • C&M Software maintains the incident resulted from social engineering, not flaws in its controls, and offered full assistance to investigators.

Wider Implications & Takeaways

  1. Insider Threats Matter Once Again: This incident is a reminder that strong controls may mean little with a credible insider, and the chance of human failure, which is often the last line of defense.
  2. PIX System Under Pressure: PIX has been used by over 76% of the Brazilian population since November 2020, and is under pressure yet again to strengthen authentication and transaction monitoring controls.
  3. Crypto as a Path for Laundering: The stolen funds’ movement into cryptocurrencies is a familiar story, and is a reminder that blockchain monitoring is an essential asset for investigating cyber attacks when stolen funds are involved.
  4. Promoting Supply-Chain Security: The hack is a good reminder for financial services players, in that they must insure their own environments and also will be required to closely monitor their vendors and third-party partner providers.

What’s Next

Investigators are expanding their probe beyond Roque—police say at least four accomplices have been identified. While a significant portion of the stolen money has been recovered, tracking the remaining sum—much of which may have been converted into crypto—is underway. The Central Bank has reinforced security controls, and PIX access via third parties like C&M remains under close scrutiny.

Conclusion

This daring digital heist showcases a warning in the realm of digital currency: a breakdown anywhere in a system, even one as structural as Brazil’s PIX system, can lead to failure because of misplaced assumptions about human trust. As Brazil looks to what it can do to recover funds and improve security, these situations show that defense against cyber crime takes codependence in defense along the chain.

Tweet60SendShare17
Previous Post

Ubisoft Sparks Uproar Over New EULA That Lets It Delete Your Games Anytime

Next Post

Capgemini Announces its Intention to Acquire WNS (Holdings) Limited

Anindya Paul

Professional content creator with strong expertise in content writing, filmmaking and social media strategy. Skilled in digital storytelling, scriptwriting, video production, sound design and graphic design - crafting compelling narratives across platforms. Known for delivering high-quality, engaging content under tight deadlines. A collaborative team player with a sharp creative instinct, adaptability to evolving trends, and a focus on impactful, results-driven communication.

Recommended For You

Japan’s Pension Sector Tests the Waters: Corporate Fund to Allocate 1% to Cryptocurrency

by Anindya Paul
June 22, 2026
0
Japan's

The normally risk-averse arena of Japan's retirement system is undergoing significant changes. For the first time, a company's pension fund has made a formal announcement that it will...

Read more

BRC-20 Tokens Explained: What They Are and How They Work on Bitcoin

by Anindya Paul
June 22, 2026
0
Bitcoin

Throughout history, Bitcoin has been regarded as both an online currency and a way of storing value. By contrast to other blockchain systems (e.g., Ethereum), Bitcoin was never...

Read more

How Bitcoin ETF Taxes Work: A Complete Guide for Investors

by Anindya Paul
June 21, 2026
0
Bitcoin ETF

The issuance of Bitcoin exchange-traded funds (ETFs) has boosted investor confidence in cryptocurrency investments. Now, rather than physically owning and storing their investments through digital currency exchanges or...

Read more
Next Post
Capgemini

Capgemini Announces its Intention to Acquire WNS (Holdings) Limited

Please login to join discussion

Techstory

Tech and Business News from around the world. Follow along for latest in the world of Tech, AI, Crypto, EVs, Business Personalities and more.
reach us at info@techstory.in

Advertise With Us

Reach out at - info@techstory.in

Aviator Game India 2026

BROWSE BY TAG

#Crypto #howto 2024 acquisition AI amazon Apple Artificial Intelligence bitcoin Business China cryptocurrency e-commerce electric vehicles Elon Musk Ethereum facebook funding Gaming Google India Instagram Investment ios iPhone IPO Market Markets Meta Microsoft News OpenAI samsung Social Media SpaceX startup startups tech technology Tesla TikTok trend trending twitter US

© 2025 Techstory.in

No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to

© 2025 Techstory.in

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?